CVE-2026-59306: Potential for deserialization of untrusted types in Spring Cloud Stream
Published Aug 27, 2026
·Updated
Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6
Affected Software
3 affected components
Spring Cloud Stream>=5.0.0<=5.0.2
Spring Cloud Stream>=4.3.0<=4.3.3
Spring Cloud Stream>=4.2.0<=4.2.6
Event History
Aug 27, 2026
CVE Published
via MITRE·06:04 PM
Data Sourced
via MITRE·06:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverity
Frequently Asked Questions
1
Which Spring Cloud Stream versions are affected?
Affected releases are Spring Cloud Stream 5.0.0 through 5.0.2, 4.3.0 through 4.3.3, and 4.2.0 through 4.2.6.
2
What level of access and interaction does exploitation require?
The supplied vector indicates network reachability, high attack complexity, high privileges, and user interaction are required. Successful exploitation may affect confidentiality and integrity, while no availability impact is indicated.